THREATOPS
THREAT OPSThreat News › Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

medcisco_psirtPublished 2026-09-16

<p>Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.</p> <p>These vulnerabilities are due to the lack of server-side validation of <em>Administrator&nbsp;</em>permissions. An attacker could

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1